Everything you need to know about how we secure the platform โ and how you can verify it.
AravaliStack is built for regulated environments. This page documents our security posture, certifications, and how we respond to vulnerabilities.
Where we stand today.
We operate a responsible disclosure programme. If you find a security vulnerability in AravaliStack, we want to hear from you โ and we commit to acknowledging your report within 48 hours.
Zero Trust at Layer 1
Security is not a layer we add to the top of the platform. It is the architectural substrate โ every component is designed with zero trust as a non-negotiable constraint.
Policy as Auditable Code
Every security policy is a version-controlled document. Auditors can review the history of every security decision, who approved it, and when it took effect.
No Long-Lived Credentials
Machine identities are short-lived and rotated automatically. No static API keys. No long-lived service account passwords. Every credential has a defined expiry.
- Report to: hello@aravalistack.com (GPG key available)
- Acknowledgement within 48 hours
- Patch release timeline communicated within 7 days
- Researcher credited in security advisory (if desired)
- We commit to no legal action against good-faith researchers
- Certification Ready
- Information security management system aligned to ISO 27001 requirements. Audit evidence available for enterprise customers.
- Architecture Aligned
- Platform architecture designed to meet PCI-DSS v4.0 requirements for cardholder data environments. Network segmentation and access controls pre-built.
- Capability Certified
- Technical, administrative, and physical safeguards aligned to HIPAA requirements. Business Associate Agreement available.
- DPDP Act 2023
- Platform designed for full compliance with India's Digital Personal Data Protection Act โ data residency, consent management, and audit trail requirements.
- Independent Security Testing
- AravaliStack conducts annual third-party penetration testing across all platform components. Results are summarised and available under NDA to enterprise prospects. Our last test was conducted in Q4 2025 by a CERT-IN empanelled security firm. No critical findings were unresolved at the time of platform release.
- How We Handle Vulnerabilities
- Our Security Architecture Principles
Security questions? We answer them directly.
Talk to our security team โ not a questionnaire portal.
